Sophos

Troj/Dloader-CT

Aliases
  • TrojanDownloader.Win32.Small.wv
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from December 2004 (3.88)
Protection available since 13 October 2004 11:10:11 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloader-CT is a downloader Trojan which attempts to download and execute various components.

The following components are downloaded into the Windows system folder:
toolbar.exe [Sophos detect as Troj/Dloader-CW]
dktibs.exe [Sophos detect as Troj/Dloader-CV]
systime.exe [Sophos detect as Troj/StartPa-CR]
sex.exe [Sophos detect as Dial/Kotud-A]

The Trojan also modifies the HOSTS file and attempts to terminate the following processes:

services.exe
msxmidi.exe
bitmap.tmp
file.exe
exploit.exe
fucker.exe
winmm64.exe
s-PEPE.exe
PEPEmsPE.exe
lpt.exe
ir.exe
intron.exe
intronet.exe
twink64.exe
usb.exe
teur.exe
host32.exe
sidefind.exe
alchem.exe
powerscan.exe
bdl74125.exe
Installer2.exe
ttgkirnl.exe
bargains.exe
WinClt.exe
Winad.exe
istsvc.exe
actalert.exe
optimize.exe
iinstall.exe
fnnmqi.exe
exdl.exe
printer.exe
printer32.exe
ykyrtws.exe
loadclean.exe
telnet.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer